2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37605 | HIGH | 7.5 | 1.3% | Aug 5, 2021 | In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only... |
| CVE-2021-37604 | HIGH | 7.5 | 1.2% | Aug 5, 2021 | In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of... |
| CVE-2021-38095 | HIGH | 7.5 | 2.0% | Aug 5, 2021 | The REST API in Planview Spigit 4.5.3 allows remote unauthenticated attackers to query sensitive user accounts data, as ... |
| CVE-2021-32603 | MEDIUM | 6.5 | 0.7% | Aug 5, 2021 | A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and belo... |
| CVE-2021-32598 | MEDIUM | 4.3 | 0.8% | Aug 5, 2021 | An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability In FortiManager a... |
| CVE-2021-3539 | MEDIUM | 5.4 | 0.5% | Aug 4, 2021 | EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-... |
| CVE-2021-36805 | MEDIUM | 4.8 | 0.6% | Aug 4, 2021 | Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the... |
| CVE-2021-36804 | HIGH | 8.1 | 1.0% | Aug 4, 2021 | Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy... |
| CVE-2021-36803 | MEDIUM | 5.4 | 0.6% | Aug 4, 2021 | Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in pro... |
| CVE-2021-36802 | MEDIUM | 6.5 | 0.9% | Aug 4, 2021 | Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed 'lo... |
| CVE-2021-36801 | HIGH | 8.1 | 1.1% | Aug 4, 2021 | Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, compani... |
| CVE-2021-36800 | CRITICAL | 9.1 | 1.5% | Aug 4, 2021 | Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. ... |
| CVE-2021-31869 | HIGH | 7.5 | 1.1% | Aug 4, 2021 | Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the ... |
| CVE-2021-31867 | HIGH | 7.5 | 1.2% | Aug 4, 2021 | Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the ... |
| CVE-2021-38115 | MEDIUM | 6.5 | 1.9% | Aug 4, 2021 | read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2 allows remote attackers to cause a deni... |
| CVE-2021-38114 | MEDIUM | 5.5 | 1.0% | Aug 4, 2021 | libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the init_vlc function, a similar issue to CVE-201... |
| CVE-2021-38113 | MEDIUM | 5.4 | 0.5% | Aug 4, 2021 | In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7, inserting JavaScript into the Add Bo... |
| CVE-2021-32465 | HIGH | 8.8 | 4.3% | Aug 4, 2021 | An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 ... |
| CVE-2021-32464 | HIGH | 7.8 | 0.6% | Aug 4, 2021 | An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and... |
| CVE-2021-24014 | MEDIUM | 6.1 | 0.6% | Aug 4, 2021 | Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before... |
| CVE-2021-22124 | HIGH | 7.5 | 1.0% | Aug 4, 2021 | An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 throug... |
| CVE-2021-20028 | CRITICAL | 9.8 | 30.1% | Aug 4, 2021 | Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Acce... |
| CVE-2021-38111 | HIGH | 8.8 | 1.3% | Aug 4, 2021 | The DEF CON 27 badge allows remote attackers to exploit a buffer overflow by sending an oversized packet via the NFMI (N... |
| CVE-2021-34707 | MEDIUM | 6.5 | 1.1% | Aug 4, 2021 | A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remot... |
| CVE-2021-32793 | MEDIUM | 4.8 | 0.8% | Aug 4, 2021 | Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prio... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now